Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3625. PoCs published by Greg Miernicki.
AI-analyzed exploit summary The provided text describes a local file disclosure vulnerability in Sahana 0.6.2.2 due to inadequate input validation. An attacker can exploit this by manipulating the 'stream' and 'mod' parameters to read arbitrary local files, such as '/etc/passwd'.
Description
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
Exploits (1)
The provided text describes a local file disclosure vulnerability in Sahana 0.6.2.2 due to inadequate input validation. An attacker can exploit this by manipulating the 'stream' and 'mod' parameters to read arbitrary local files, such as '/etc/passwd'.